Gateway Service Configuration

Introduction

The Infinite Scale Gateway service is responsible for passing requests to the storage providers. Other services never talk to storage providers directly but will always send their requests via this service.

Default Values

  • Gateway listens on port 9142 by default.

Caching

The gateway service can use a configured store via the global OCIS_CACHE_STORE environment variable.

Note that for each global environment variable, an independent service-based one might be available additionally. For precedences see Environment Variable Notes. Check the configuration section below. Supported stores are:

Store Type Description

memory

Basic in-memory store. Will not survive a restart.
Usually the default for caches. See the store environment variable for which one is used.

nats-js-kv

Stores data using key-value-store feature of NATS JetStream.
Usually the default for stores, see the store environment variable for which one is used.

redis-sentinel

Stores data in a configured Redis Sentinel cluster.

noop

Stores nothing. Useful for testing. Not recommended in production environments.

The gateway service can only be scaled if not using the memory store and the stores are configured identically over all instances!
If you have used one of the deprecated stores of a former version, you should reconfigure to use one of the supported ones as the deprecated stores will be removed in a later version.
Store specific notes
  • When using redis-sentinel:
    The Redis master to use is configured via e.g. OCIS_CACHE_STORE_NODES in the form of <sentinel-host>:<sentinel-port>/<redis-master> like 10.10.0.200:26379/mymaster.

  • When using nats-js-kv:

    • It is recommended to set OCIS_CACHE_STORE_NODES to the same value as OCIS_EVENTS_ENDPOINT. That way the cache uses the same nats instance as the event bus. See the Event Bus Configuration for more details.

    • Authentication can be added, if configured, via OCIS_CACHE_AUTH_USERNAME and OCIS_CACHE_AUTH_PASSWORD.

    • It is possible to set OCIS_CACHE_DISABLE_PERSISTENCE to instruct nats to not persist cache data on disc.

Event Bus Configuration

The Infinite Scale event bus can be configured by a set of environment variables.

  • If you are using a binary installation as described in Minimal Bare Metal Deployment or Bare Metal with systemd, the address of the event bus OCIS_EVENTS_ENDPOINT is predefined as localhost address without the need for further configuration, but changeable on demand.

  • In case of an orchestrated installation like with Docker or Kubernetes, the event bus must be an external service for scalability like a Redis Sentinel cluster or a key-value-store NATS JetStream. Both named stores are supported and also used in Caching and Persistence. The store used is not part of the Infinite Scale installation and must be separately provided and configured.

  • Note that from a configuration point of view, caching and persistence are independent of the event bus configuration.

Note that for each global environment variable, a service-based one might be available additionally. For precedences see Environment Variable Notes. Check the configuration section below.

Without the aim of completeness, see the list of environment variables to configure the event bus:

Envvar Description

OCIS_EVENTS_ENDPOINT

The address of the event system.

OCIS_EVENTS_CLUSTER

The clusterID of the event system. Mandatory when using NATS as event system.

OCIS_EVENTS_ENABLE_TLS

Enable TLS for the connection to the events broker.

OCIS_INSECURE

Whether to verify the server TLS certificates.

OCIS_EVENTS_AUTH_USERNAME

The username to authenticate with the events broker.

OCIS_EVENTS_AUTH_PASSWORD

The password to authenticate with the events broker.

Configuration

Environment Variables

The gateway service is configured via the following environment variables. Read the Environment Variable Types documentation for important details. Column IV shows with which release the environment variable has been introduced.

  • 7.0.0

Environment variables for the gateway service
Name IV Type Default Value Description

OCIS_TRACING_ENABLED
GATEWAY_TRACING_ENABLED

pre5.0

bool

false

Activates tracing.

OCIS_TRACING_TYPE
GATEWAY_TRACING_TYPE

pre5.0

string

The type of tracing. Defaults to '', which is the same as 'jaeger'. Allowed tracing types are 'jaeger' and '' as of now.

OCIS_TRACING_ENDPOINT
GATEWAY_TRACING_ENDPOINT

pre5.0

string

The endpoint of the tracing agent.

OCIS_TRACING_COLLECTOR
GATEWAY_TRACING_COLLECTOR

pre5.0

string

The HTTP endpoint for sending spans directly to a collector, i.e. http://jaeger-collector:14268/api/traces. Only used if the tracing endpoint is unset.

OCIS_LOG_LEVEL
GATEWAY_LOG_LEVEL

pre5.0

string

The log level. Valid values are: 'panic', 'fatal', 'error', 'warn', 'info', 'debug', 'trace'.

OCIS_LOG_PRETTY
GATEWAY_LOG_PRETTY

pre5.0

bool

false

Activates pretty log output.

OCIS_LOG_COLOR
GATEWAY_LOG_COLOR

pre5.0

bool

false

Activates colorized log output.

OCIS_LOG_FILE
GATEWAY_LOG_FILE

pre5.0

string

The path to the log file. Activates logging to this file if set.

GATEWAY_DEBUG_ADDR

pre5.0

string

127.0.0.1:9143

Bind address of the debug server, where metrics, health, config and debug endpoints will be exposed.

GATEWAY_DEBUG_TOKEN

pre5.0

string

Token to secure the metrics endpoint.

GATEWAY_DEBUG_PPROF

pre5.0

bool

false

Enables pprof, which can be used for profiling.

GATEWAY_DEBUG_ZPAGES

pre5.0

bool

false

Enables zpages, which can be used for collecting and viewing in-memory traces.

OCIS_GATEWAY_GRPC_ADDR
GATEWAY_GRPC_ADDR

pre5.0

string

127.0.0.1:9142

The bind address of the GRPC service.

OCIS_GRPC_PROTOCOL
GATEWAY_GRPC_PROTOCOL

pre5.0

string

tcp

The transport protocol of the GRPC service.

OCIS_JWT_SECRET
GATEWAY_JWT_SECRET

pre5.0

string

The secret to mint and validate jwt tokens.

OCIS_REVA_GATEWAY

pre5.0

string

com.owncloud.api.gateway

The CS3 gateway endpoint.

OCIS_GRPC_CLIENT_TLS_MODE

pre5.0

string

TLS mode for grpc connection to the go-micro based grpc services. Possible values are 'off', 'insecure' and 'on'. 'off': disables transport security for the clients. 'insecure' allows using transport security, but disables certificate verification (to be used with the autogenerated self-signed certificates). 'on' enables transport security, including server certificate verification.

OCIS_GRPC_CLIENT_TLS_CACERT

pre5.0

string

Path/File name for the root CA certificate (in PEM format) used to validate TLS server certificates of the go-micro based grpc services.

GATEWAY_SKIP_USER_GROUPS_IN_TOKEN

pre5.0

bool

false

Disables the loading of user’s group memberships from the reva access token.

GATEWAY_COMMIT_SHARE_TO_STORAGE_GRANT

pre5.0

bool

true

Commit shares to storage grants. This grants access to shared resources for the share receiver directly on the storage.

GATEWAY_SHARE_FOLDER_NAME

pre5.0

string

Shares

Name of the share folder in users' home space.

GATEWAY_DISABLE_HOME_CREATION_ON_LOGIN

pre5.0

bool

true

Disable creation of the home space on login.

OCIS_TRANSFER_SECRET

pre5.0

string

The storage transfer secret.

GATEWAY_TRANSFER_EXPIRES

pre5.0

int

86400

Expiry for the gateway tokens.

OCIS_CACHE_STORE
GATEWAY_PROVIDER_CACHE_STORE

pre5.0

string

noop

The type of the cache store. Supported values are: 'memory', 'redis-sentinel', 'nats-js-kv', 'noop'. See the text description for details.

OCIS_CACHE_STORE_NODES
GATEWAY_PROVIDER_CACHE_STORE_NODES

pre5.0

[]string

[127.0.0.1:9233]

A list of nodes to access the configured store. This has no effect when 'memory' store is configured. Note that the behaviour how nodes are used is dependent on the library of the configured store. See the Environment Variable Types description for more details.

OCIS_CACHE_DATABASE

pre5.0

string

cache-providers

The database name the configured store should use.

OCIS_CACHE_TTL
GATEWAY_PROVIDER_CACHE_TTL

pre5.0

Duration

5m0s

Default time to live for user info in the cache. Only applied when access tokens has no expiration. See the Environment Variable Types description for more details.

OCIS_CACHE_DISABLE_PERSISTENCE
GATEWAY_PROVIDER_CACHE_DISABLE_PERSISTENCE

5.0

bool

false

Disables persistence of the provider cache. Only applies when store type 'nats-js-kv' is configured. Defaults to false.

OCIS_CACHE_AUTH_USERNAME
GATEWAY_PROVIDER_CACHE_AUTH_USERNAME

5.0

string

The username to use for authentication. Only applies when store type 'nats-js-kv' is configured.

OCIS_CACHE_AUTH_PASSWORD
GATEWAY_PROVIDER_CACHE_AUTH_PASSWORD

5.0

string

The password to use for authentication. Only applies when store type 'nats-js-kv' is configured.

OCIS_CACHE_STORE
GATEWAY_CREATE_HOME_CACHE_STORE

pre5.0

string

memory

The type of the cache store. Supported values are: 'memory', 'redis-sentinel', 'nats-js-kv', 'noop'. See the text description for details.

OCIS_CACHE_STORE_NODES
GATEWAY_CREATE_HOME_CACHE_STORE_NODES

pre5.0

[]string

[127.0.0.1:9233]

A list of nodes to access the configured store. This has no effect when 'memory' store is configured. Note that the behaviour how nodes are used is dependent on the library of the configured store. See the Environment Variable Types description for more details.

OCIS_CACHE_DATABASE

pre5.0

string

cache-createhome

The database name the configured store should use.

OCIS_CACHE_TTL
GATEWAY_CREATE_HOME_CACHE_TTL

pre5.0

Duration

5m0s

Default time to live for user info in the cache. Only applied when access tokens has no expiration. See the Environment Variable Types description for more details.

OCIS_CACHE_DISABLE_PERSISTENCE
GATEWAY_CREATE_HOME_CACHE_DISABLE_PERSISTENCE

5.0

bool

false

Disables persistence of the create home cache. Only applies when store type 'nats-js-kv' is configured. Defaults to false.

OCIS_CACHE_AUTH_USERNAME
GATEWAY_CREATE_HOME_CACHE_AUTH_USERNAME

5.0

string

The username to use for authentication. Only applies when store type 'nats-js-kv' is configured.

OCIS_CACHE_AUTH_PASSWORD
GATEWAY_CREATE_HOME_CACHE_AUTH_PASSWORD

5.0

string

The password to use for authentication. Only applies when store type 'nats-js-kv' is configured.

OCIS_URL
GATEWAY_FRONTEND_PUBLIC_URL

pre5.0

string

https://localhost:9200

The public facing URL of the oCIS frontend.

GATEWAY_USERS_ENDPOINT

7.0.0

string

com.owncloud.api.users

The endpoint of the users service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_GROUPS_ENDPOINT

7.0.0

string

com.owncloud.api.groups

The endpoint of the groups service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_PERMISSIONS_ENDPOINT

7.0.0

string

com.owncloud.api.settings

The endpoint of the permissions service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_SHARING_ENDPOINT

7.0.0

string

com.owncloud.api.sharing

The endpoint of the shares service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_AUTH_APP_ENDPOINT

7.0.0

string

com.owncloud.api.auth-app

The endpoint of the auth-app service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_AUTH_BASIC_ENDPOINT

7.0.0

string

com.owncloud.api.auth-basic

The endpoint of the auth-basic service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_AUTH_BEARER_ENDPOINT

7.0.0

string

The endpoint of the auth-bearer service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_AUTH_MACHINE_ENDPOINT

7.0.0

string

com.owncloud.api.auth-machine

The endpoint of the auth-machine service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_AUTH_SERVICE_ENDPOINT

7.0.0

string

com.owncloud.api.auth-service

The endpoint of the auth-service service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_STORAGE_PUBLIC_LINK_ENDPOINT

7.0.0

string

com.owncloud.api.storage-publiclink

The endpoint of the storage-publiclink service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_STORAGE_USERS_ENDPOINT

7.0.0

string

com.owncloud.api.storage-users

The endpoint of the storage-users service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_STORAGE_SHARES_ENDPOINT

7.0.0

string

com.owncloud.api.storage-shares

The endpoint of the storage-shares service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_APP_REGISTRY_ENDPOINT

7.0.0

string

com.owncloud.api.app-registry

The endpoint of the app-registry service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_OCM_ENDPOINT

7.0.0

string

com.owncloud.api.ocm

The endpoint of the ocm service. Can take a service name or a gRPC URI with the dns, kubernetes or unix protocol.

GATEWAY_STORAGE_REGISTRY_DRIVER

pre5.0

string

spaces

The driver name of the storage registry to use.

GATEWAY_STORAGE_REGISTRY_RULES

pre5.0

[]string

[]

The rules for the storage registry. See the Environment Variable Types description for more details.

GATEWAY_STORAGE_REGISTRY_CONFIG_JSON

pre5.0

string

Additional configuration for the storage registry in json format.

GATEWAY_STORAGE_USERS_MOUNT_ID

pre5.0

string

Mount ID of this storage. Admins can set the ID for the storage in this config option manually which is then used to reference the storage. Any reasonable long string is possible, preferably this would be an UUIDv4 format.

YAML Example

  • 7.0.0

# Autogenerated
# Filename: gateway-config-example.yaml

tracing:
  enabled: false
  type: ""
  endpoint: ""
  collector: ""
log:
  level: ""
  pretty: false
  color: false
  file: ""
debug:
  addr: 127.0.0.1:9143
  token: ""
  pprof: false
  zpages: false
grpc:
  addr: 127.0.0.1:9142
  tls: null
  protocol: tcp
token_manager:
  jwt_secret: ""
reva:
  address: com.owncloud.api.gateway
  tls:
    mode: ""
    cacert: ""
skip_user_groups_in_token: false
commit_share_to_storage_grant: true
share_folder_name: Shares
disable_home_creation_on_login: true
transfer_secret: ""
transfer_expires: 86400
cache:
  provider_cache_store: noop
  provider_cache_nodes:
  - 127.0.0.1:9233
  provider_cache_database: cache-providers
  provider_cache_ttl: 5m0s
  provider_cache_disable_persistence: false
  provider_cache_auth_username: ""
  provider_cache_auth_password: ""
  create_home_cache_store: memory
  create_home_cache_nodes:
  - 127.0.0.1:9233
  create_home_cache_database: cache-createhome
  create_home_cache_ttl: 5m0s
  create_home_cache_disable_persistence: false
  create_home_cache_auth_username: ""
  create_home_cache_auth_password: ""
frontend_public_url: https://localhost:9200
users_endpoint: com.owncloud.api.users
groups_endpoint: com.owncloud.api.groups
permissions_endpoint: com.owncloud.api.settings
sharing_endpoint: com.owncloud.api.sharing
auth_app_endpoint: com.owncloud.api.auth-app
auth_basic_endpoint: com.owncloud.api.auth-basic
auth_bearer_endpoint: ""
auth_machine_endpoint: com.owncloud.api.auth-machine
auth_service_endpoint: com.owncloud.api.auth-service
storage_public_link_endpoint: com.owncloud.api.storage-publiclink
storage_users_endpoint: com.owncloud.api.storage-users
storage_shares_endpoint: com.owncloud.api.storage-shares
app_registry_endpoint: com.owncloud.api.app-registry
ocm_endpoint: com.owncloud.api.ocm
storage_registry:
  driver: spaces
  rules: []
  json: ""
  storage_users_mount_id: ""